Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | 4homepages 4images | 8/2/2012 | 16/6/2026 | SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | 4homepages 4images | 8/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Leadcapturepagesystem Lead Capture Page System | 29/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Mikoviny WP Custom Pages | 10/4/2011 | 16/6/2026 | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Smspages | 9/7/2009 | 16/6/2026 | SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | |
| Modificada | Media (4.3) | 1.1% | — | 4homepages 4images | 8/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | 4homepages 4images | 19/6/2009 | 16/6/2026 | Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter. | |
| Modificada | Baja (3.5) | 1.6% | 💥 Exploit | 4homepages 4images | 19/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mybboard Custom Pages Plugin | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Hitachi Groupmax WEB Workflow SDK SET FOR Active Server PagesHitachi Groupmax Workflow TO Development KIT FOR Active Server Pages | 26/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi Groupmax Workflow - Development Kit for Active Server Pages before 06-52-/A allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Myiosoft Easydynamicpages | 28/7/2008 | 16/6/2026 | SQL injection vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to execute arbitrary SQL commands via the read parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Myiosoft Easydynamicpages | 28/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Pagesquid CMS | 27/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (9.3) | 16% | 💥 Exploit | Pagesperso-orange GFL SDKPagesperso-orange NconvertPagesperso-orange Xnview | 24/6/2008 | 16/6/2026 | Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file. | |
| Modificada | Alta (7.5) | 3.2% | — | SUN Java Active Server Pages | 4/6/2008 | 16/6/2026 | Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Sstreamtv Custompages | 25/3/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php. | |
| Modificada | Media (5) | 4.5% | 💥 Exploit | Postnuke Software Foundation Pagesetter | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Design4online Userpages2 | 22/2/2007 | 16/6/2026 | SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Enthrallweb Epages | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | 4homepages 4images | 11/10/2006 | 16/6/2026 | SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | User Home Pages | 5/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to… | |
| Modificada | Baja (2.6) | 1.3% | — | 4homepages 4images | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php. | |
| Modificada | Alta (7.5) | 4.9% | — | Secure Reality Phpsecurepages | 13/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Stoitsov Easydynamicpages | 17/2/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script. | |
| Modificada | Alta (7.5) | 1.9% | — | Secure Reality Phpsecurepages | 7/2/2001 | 16/6/2026 | PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code. |